CVE-2024-44112: SAP Oil %/ Gas

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as a non-administrative user could call a remote-enabled function which will allow them to delete non-sensitive entries in a user data table. There is no effect on confidentiality or availability.

Affected products

  • SAP Oil %/ Gas: version 600 only; version 602 only; version 603 only; version 604 only; version 605 only; version 606 only; …

Published 2024-09-10. Last modified 2026-06-17.